Rollback Runbook
View on GitHubWindows Identity Services Deployer/docs
Before AD Promotion
Section titled “Before AD Promotion”- Remove created artifacts, logs, and state files.
- Revert network and hostname changes as needed.
After Role Installation but Before Promotion
Section titled “After Role Installation but Before Promotion”- Uninstall explicitly added roles if approved.
- Remove DHCP scopes, DNS zones, and GPOs created by automation.
After AD Promotion
Section titled “After AD Promotion”- Evaluate whether rollback is riskier than rebuild.
- Follow AD DS recovery policy; use restore runbook for supported recovery steps.
DHCP Scope Rollback
Section titled “DHCP Scope Rollback”- Remove created scopes and reservations in reverse order.
- Verify no production clients depend on removed scopes.
GPO Rollback
Section titled “GPO Rollback”- Unlink created GPOs.
- Remove GPO objects only after impact assessment.
DNS Rollback
Section titled “DNS Rollback”- Remove reverse zones and forwarders set by automation.
- Validate AD-integrated DNS dependencies before deletion.
Service Account and Group Cleanup
Section titled “Service Account and Group Cleanup”- Remove created service accounts and groups when no longer referenced.
When Rebuild Is Cleaner Than Rollback
Section titled “When Rebuild Is Cleaner Than Rollback”- If domain promotion completed and rollback risk is high, rebuild from known-good image and restore from validated backups.